Skip to content

Inconsistent license declarations: rad-components declares ISC while the repository is Apache-2.0 #359

Description

@nicolejms

Area for Improvement

License declarations across the workspace packages.

Observed behavior

Four declarations, three different answers, and the inconsistency lands on the one package that is currently publishable:

Location Declares
LICENSE (repository root) Apache License 2.0
package.json (repository root) no license field at all
plugins/plugin-radius/package.json Apache-2.0
plugins/plugin-radius-backend/package.json Apache-2.0
packages/rad-components/package.json ISC

The root package.json is "private": true, so a missing license field there is not fatal, but it does mean the repository's own manifest asserts nothing.

The part that matters: @radapp.io/rad-components declares ISC and is not private. It is the only package in the workspace that is currently publishable, and it is the one that disagrees with the repository's LICENSE file. Anyone consuming it from a registry would be told ISC while the repository it came from says Apache-2.0.

This is almost certainly an unreviewed default from whatever scaffolded the package rather than a deliberate choice — ISC is the npm default when no license is specified interactively.

Desired behavior

Every package declares the license the project actually intends, consistent with the root LICENSE file. If Apache-2.0 is correct, rad-components is corrected and the root manifest gains an explicit license field so the intent is stated rather than inferred.

This needs a maintainer decision rather than a drive-by fix, since changing a declared license on an already-published package has implications beyond the repository.

Proposed Fix

  1. Confirm the intended license for @radapp.io/rad-components, including for versions already published under ISC.
  2. Align the package manifests.
  3. Add "license" to the root package.json.

Worth resolving before the plugin-publication work lands, because that work adds more published packages and the design also moves code between repositories — which is a bad time to have an unresolved license question.

Additional context

Pinned by PU-18 in plugins/plugin-radius/src/packaging.test.ts, added in nicolejms#1, which records the present state and fails if it drifts further.

Noted as open decision 2 in docs/design/2026-09-dashboard-plugin-test-plan.md.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    maintenancetriagedThis item has been triaged by project maintainers and is in the backlog

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions